A vulnerability has been found in parse-community parse-server up to 8.6.50/9.6.0-alpha.39 and classified as problematic . This impacts an unknown function of the component Configuration Options Handl…
cyberintel.kalymoon.com · 50387 articles · updated every 4 hours · grows forever
A vulnerability has been found in parse-community parse-server up to 8.6.50/9.6.0-alpha.39 and classified as problematic . This impacts an unknown function of the component Configuration Options Handl…
A vulnerability was found in parse-community parse-server up to 8.6.51/9.6.0-alpha.40 and classified as critical . Affected is an unknown function. Executing a manipulation can lead to improper authen…
A vulnerability was found in ellite Wallos up to 4.7.1 . It has been classified as problematic . Affected by this vulnerability is an unknown functionality of the component Password Reset Token Handle…
A vulnerability was found in parse-community parse-server up to 8.6.52/9.6.0-alpha.41 . It has been declared as problematic . Affected by this issue is some unknown functionality of the component Live…
A vulnerability was found in Froxlor up to 2.3.4 . It has been rated as problematic . This affects the function DomainZones.add of the component API Endpoint . This manipulation causes injection. The …
A vulnerability categorized as problematic has been discovered in parse-community parse-server up to 8.6.60/9.6.0-alpha.54 . This vulnerability affects unknown code of the component Endpoint . Such ma…
A vulnerability identified as problematic has been detected in parse-community parse-server up to 8.6.56/9.6.0-alpha.47 . This issue affects some unknown processing of the component REST API . Perform…
A vulnerability labeled as problematic has been found in parse-community parse-server up to 8.6.57/9.6.0-alpha.51 . Impacted is an unknown function. Executing a manipulation can lead to resource consu…
This research report explores the layers of agent intent and how to align them for secure enterprise AI adoption. The post Governing AI agent behavior: Aligning user, developer, role, and organization…
7AI's Lior Div on Building Knowledge Graphs, Human Oversight to Drive AI Accuracy Security teams face an AI reality check as tools require deep organizational context to deliver value. Lior Div, co-fo…
A persistent threat actor known as Larva-26002 has been continuously targeting poorly managed Microsoft SQL (MS-SQL) servers, this time deploying a new scanner malware called ICE Cloud Client. The cam…
A threat actor known as TeamPCP has taken a sharp turn toward destruction with a new payload that goes far beyond credential theft or backdoor installation. The group, tracked as a cloud-native attack…
Cybercriminals behind Tycoon2FA, a phishing-as-a-service (PhaaS) platform, have resumed targeting cloud accounts with near-full force despite a coordinated law enforcement takedown on March 4, 2026. E…
A recent security analysis has revealed how chaining seemingly minor logic flaws in Dell Wyse Management Suite (WMS) On-Premises can result in a complete system compromise. Security researchers demons…
HackerOne recently disclosed a data breach affecting 287 of its employees following a cyberattack on its U.S. benefits administrator, Navia Benefit Solutions. The breach stemmed from a Broken Object L…
The attacks included a destructive infiltration of Poland's energy system in December and was suspected of originating in Russia. The post Poland Faced a Surge in Cyberattacks in 2025, Including a Maj…
Agentic AI platforms are shifting from passive recommendation tools to autonomous action-takers with real system access, The post Why Agentic AI Systems Need Better Governance – Lessons from OpenClaw …
CESER’s Project Armor is a five year initiative to harden the US critical energy infrastructure, including strengthening energy systems ‘to prevent and recover from wildfires and other hazards’. The p…
An ongoing phishing campaign is targeting French-speaking corporate environments with fake resumes that lead to the deployment of cryptocurrency miners and information stealers. "The campaign uses hig…
A large-scale malvertising campaign active since January 2026 has been observed targeting U.S.-based individuals searching for tax-related documents to serve rogue installers for ConnectWise ScreenCon…
TeamPCP, the threat actor behind the recent compromises of Trivy and KICS, has now compromised a popular Python package named litellm, pushing two malicious versions containing a credential harvester,…